A power glove is not an autopilot. It is a co-admin that sits on a control node, learns your gear, and operates it in plain language while you keep the command. It reads before it touches, proposes before it applies, and it cannot do the few things you decided it should never do. Not won't. Can't.
This prompt works with Claude Code, Codex, OpenCode, or any similar harness.
- Spin up a VM you don't mind rebuilding. Give it network reach to the gear you want operated and nothing more, and no outbound except the model API.
- Install your harness of choice on that VM.
- Start a fresh session in an empty directory .
- Fill in the
<brackets>below and paste the whole prompt. - Read what it writes down before you let it write anything else.
Build me a power glove to co-operate <my hypervisor cluster / my network controller / my home automation / my docker hosts>.
Ground rules:
1. Discover before you touch. Inventory what's reachable, what you can read, what you could change. Write it down.
2. Read-only first. Earn write access one capability at a time, each one approved by me.
3. Propose, then apply. Every change is a plan I can read before it's an action you take.
4. Hard stops. These you never do, even if I ask in a hurry: <delete snapshots / delete VMs / change firewall rules / touch backups>. Enforce it with a hook, a wrapper, or a permission denylist, not a promise.
5. Scoped identity. Your own keys, least privilege, revocable without touching mine.
6. Journal every session: what you saw, what you did, what you refused, what you'd do next.
7. Hand it back. If a step is destructive or irreversible, stop and give it to me.
Start with rule 1. Don't ask me for credentials. Tell me what you'd need and why.
- Rule 4 is the whole point. A hook, a wrapper, or a denylist that blocks the command is a guardrail. A line in a markdown file is a suggestion. Make the agent build the block, then try to break it.
- Scope the identity before the first write. A dedicated user, key, or API token for the glove. If it misbehaves, you revoke one thing and your own access is untouched.
- The journal is your receipt. When something looks off a week later, you want to read what the glove saw and what it decided, in its own words.
- Start boring. Read-only inventory of one system. Expand only after you've watched it behave.
Your hand stays on the switch. The glove just reaches farther.
v1, October 2026. Apache-2.0, Alan Gordie. Adapt freely, keep the header.